CVE-2014-1539
Published Jun 11, 2014
Last updated 7 years ago
Overview
- Description
- Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a DIV element, which makes it easier for remote attackers to conduct clickjacking attacks via JavaScript code that produces a fake cursor image.
- Source
- security@mozilla.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8B8514D-277D-4D79-84E3-73BF050CE927", "versionEndIncluding": "29.0.1" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0B063ED-8BD8-4E14-8990-D23CCB0A20BB", "versionEndIncluding": "24.6" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:24.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CCAFDF1-10BB-4AB0-9C9D-E99DDBA901BB" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:24.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31EE89B8-705F-4A05-9015-3D6E81D394E9" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:24.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E30AE3D4-6A3E-435E-BDBF-1A9A17297433" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:24.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0C705A0-62C0-485A-A077-C7DD426F80B5" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:24.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66C802A7-E4D5-4D2D-9CE8-749A75DF7461" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:24.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E8A57FA-AC27-4288-8E42-97DECF3B993C" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:24.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D474B11-98D0-41A3-A98B-CFB6955264AE" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:24.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BBD940E-9EF0-460B-A721-E70C719F2244" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0FF5999A-9D12-4CDD-8DE9-A89C10B2D574" } ], "operator": "OR" } ], "operator": "AND" } ]